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Amendments to the Claims: 

This Usting of claims will replace all prior versions, and Ustings, of claims in the 

application: 
Listing of Claims; 

1 . (Currently Amended) A method to protect a file system from a viral infection, 
comprising: 

flagging a program on a computer as being suspect for possibly containing a virus 
without p e rforming any viruo ocamiing and dotoction actions in response to at least one of: 

opening a local file on a local file system of the computer to perform a read 
operation and opening a shared file on a shared or network file system to perform a write or append 
operation with the local file; 

the program reading or opening itself and the program attempting to write or 
append any content to the shared file on the shared or network file system or to write or append any 
content to the local file on the local file system; 

the program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system; 
and 

the program attempting to write or append a remote file to the local file 

system; 

storing a filename and a location where the local or shared file is copied or written in 
response to the local or shared file being copied or written by the progra m wthout performing any 
virus scanning and dotoction actions . 

2. (Previously Amended) The method of claim 1, further comprising inhibiting a write or 
append operation associated with the program in response to flagging the program. 

3. (Origmal) The method of claim 1, further comprising monitoring all file operations 
associated with the program in response to the program not being in a safe Ust. 
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4. (Original) The method of claim 1, further comprising permitting selected read and write 
operations in response to a predefined rules table. 

5. (Original) The method of claim 1, further comprising sending an alert in response to 
flagging the program. 

6. (Canceled) 

7. (Original) The method of claim 1, further comprising sending an alert to a network 
monitoring system in response to flagging the program. 

8. (Original) The method of claim 1, fiu^her comprising logging any file system operations 
including recording a filename and a location where the local or shared file is written. 

9. (Currently Amended) A method to protect a file system firom a viral infection, 
comprising: 

allowing a security level to be set; 

monitoring predetermined file system operations associated with a program; and 
logging any predetermined file system operations associated with the program 

including recording a filename and a location where a file is written witiiout performing any viruo 

f^n^^"^"C ''"^ rlntnntinn nntinnfi in response to the file being written . 

10. (Original) The method of claim 9, fiirther comprising selecting the program for 
monitoring in response to the program not being on a safe Ust. 

1 1 . (Original) The method of claim 1 0, further comprising logging any file system 
operations associated with any programs on the safe Ust. 

12. (Original) The method of claim 9, fiirther comprising receiving a notification that the 
program intends to perform one of the predetermined file system operations. 
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13. (Previously Amended) The method of claim 9, further comprising following a 
predefined procedure in response to the level of security set. 

14. (Original) The method of claim 9, further comprising flagging the program in response 
to the program attempting to perform one of the predetermined file system operations. 

15. (Original) The method of claim 14, fiirther comprising flagging the program in 
response to at least one of: 

the program opening a local file on a local file system to perform a read operation 
and opening a shared file on a shared or network file system to perform a write or append operation 
with the local file; 

the program reading or opening itself and the program attempting to write or append 
any content to the shared file on the shared or network file system or to write or append any content 
to the local file on the local file system; 

the program attempting to write or append the local file to the shared or network file 
system and preserve a filename of the local file m the shared or network file system; and 

the program attempting to write or append a remote file to the local file system. 

16. (Original) The method of claim 14 , fiirther comprising inhibiting any predetermined 
file system operations associated with the program in response to the program being flagged. 

17. (Original) The method of claim 9, fiirther comprising sending an alert in response to the 
program attempting to perform any predetermined file system operations. 

18. (Original) The method of claim 17, further comprising sending the alert to a network 
monitoring system. 

19. (Original) The method of claim 9, fiirther comprising presenting an alert to a user for 
approval before the predetermined file system operation is performed by the program. 
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20. (Current Amended) The method ofclaim 9, further comprising requiring approval 
before performing any predetermined file system operations associated wife the program in 
response to the program not being on a safe hst. 

21 . (Currently Amended) A system to protect a file system from a viral infection, 
comprising: 

a file system protection program operable on a computer including: 

means to monitor predetermined file system operations associated with 

another program; 

a plurality of settable levels of security; 

a predefined procedure associated with each level of security to be followed 
in response to a current level of security being set for the predefined procedure and in 
response to an intent to perform a particular file system operation also associated 
with the currently set level of security; and 

means to log any predetermined file system operations associated with the 
other program including recording a filename and a location where a file is written 
ivithout pOTf^rrpi^g ^^y vi^-"" r-mnning nnd d e t e ction actions after the file is written . 

22. (Original) The system ofclaim 21, fiirther comprising a safe hst, wherein the file 
system program is adapted to monitor the other program in response to the other program not being 
on the safe Ust. 

23. (Original) The system ofclaim 21, further comprising a log to record any 
predetermined file system operations. 

24. (Original) The system of claim 21, fiirther comprising mems to flag the other program 

in response to at least one of: 

the other program opening a local file on a local file system to perform a read 
operation and opening a shared file on a shared or network file system to perform a write or append 
operation with the local file; 
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the other program reading or opening itself and the other program attempting to write 
or append itself or any content to the shared file on the shared or network file system or to write or 
append itself or any content to the local file on the local file system; 

the other program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system; 
and 

the other program attempting to write or append a remote file to the local file system. 

25. (Original) The system of claim 21, fiirther comprising means to flag the other program 
in response to the other program attempting to perform one of the predetermined file system 
operations. 

26. (Original) The system of claim 25, fiirther comprising means to send an alert in 
response to flagging the other program. 

27. (Original) The system of claim 25, fiirther comprising: 

a network monitoring system; and 

means to send an alert to the network monitoring system in response to flagging the 
other program. 

28. (Currently Amended) The system of claim 25, ftuther comprising means to inhibit 
predetermined file system operations associated with the other program in response to the other 
program efeer being flagged. 

29. (Original) The system of claim 25, fiirther comprising: 

means to present an alert to a user; and 

means for the user to approve the one of the predetermined file system operations 
before being performed by the other program. 
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30. (Currently Amended) A method of making system to protect a file system fi-om a viral 

infection, comprising: 

providing a file system protection program including: 

providing means to monitor predetermined file system operations associated 

with another program, 

defining a plurality of settable levels of security; 

providing a predefined procedure associated with each level of security to be 
followed in response to a current level of security being set for the predefined 
procedure and in response to an intent to perform a particular file system operation 
also associated with the currently set level of security; and 

providing means to log any predetermined file system operations associated 
with the other program including recording a filename and a location where a file is written without 
porformi"g ""y '^i"'" nnnnTiing nnd dotootion aotiona in response to the file be i ng written . 

3 1 . (Original) The method of claim 30, further comprising: 

providing a safe hst; and 

adapting the file system protection program to monitor the other program in response 
to the other program not being on the safe hst. 

32. (Original) The method of claim 30, fiirther comprising forming a log to record any 
predetermined file system operations. 

33. (Original) The method of claim 30, further comprising providing means to flag the 
other program in response to at least one of: 

the other program opening a local file on a local file system to perform a read 
operation and opening a shared file on a shared or network file system to perform a write or append 
operation with the local file; 

the other program reading or opening itself and the other program attempting to write 
or append itself or any content to the shared file on the shared or network file system or to write or 
append itself or any content to the local file on tiie local file system; 
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the other program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system; 
and 

the other program attempting to write or append a remote file to the local file system. 

34. (Original) The method ofclaim 30, fiirther comprising providing means to flag the 
other program in response to the other program attempting to perform one of the predetermined file 
system operations. 

35. (Original) The method ofclaim 34, fiirther comprising providing means to send an 
alert in response to flagging the other program. 

36. (Original) The method of claim 34, fiuther comprising: 
providing a network monitoring system; and 

providing means to send an alert to the network monitoring system in response to 
flagging the other program. 

37. (Original) The method ofclaim 34, fiirther comprising: 
providing means to present an alert to a user; and 

providing means for the user to approve the one of the predetermined file system 
operations before being performed by the other program. 

38. (Currently Amended) A computer-readable tangible medium having computer- 
executable mstructions for performing a method on a computer , comprising: 

allowing a security level to be set on the computer ; 

monitoring predetermined file system operations associated with a program; and 
logging any predetermined file system operations associated with the program 

including recording a filename and a location where a file is written without performing any virua 

urnnniTij; nnd det e ction aotiono in rcsponse to the file being written . 
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39. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising selecting the program for monitoring in 
response to the program not being on a safe list. 

40. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising following a predefined procedure in 
response to a level of security set. 

41 . (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising flagging the program in response to the 
program attempting to perform one of the predetermined file system operations. 

42. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 41, further comprising flagging the program in response to at least 

one of: 

the program opening a local file on a local file system to perform a read operation 
and opening a shared file on a shared or network file system to perform a write or append operation 
with the local file; 

the program reading or opening itself and the program attempting to write or append 
itself or any content to the shared file on the shared or network file system or to write or append 
itself or any content to the local file on the local file system; 

the program attempting to write or append the local file to the shared or network file 
system and preserve a filename of the local file in the shared or network file system; and 

the program attempting to write or append a remote file to the local file system. 

43. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claun 41, fiirther comprising inhibiting any predetermined file system 
operations associated with the program in response to the program being flagged. 
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44. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising sending an alert in response to the program 
attempting to perform any predetermined file system operations. 
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